Splunk Search

Splunk Search
Community Activity
ivonnepena
I am trying to create new fields to search across multiple sources. I have two problems: When searching for data of ...
by ivonnepena New Member in Splunk Search 08-04-2016
0 3
0
3
phudinhha
Dear Team, What i am trying to achieve is like this: I have a lookup table with many subnets. I am trying to match t...
by phudinhha Explorer in Splunk Search 08-04-2016
1 4
1
4
janderson19
Hello, I'm working on a search for blackboard that will return users who have failed to log in more than 3 times in ...
by janderson19 Path Finder in Splunk Search 08-04-2016
0 4
0
4
jph11
Currently working on an integration betweek Splunk and RSA Archer eGRC. We are working with the security operations m...
by jph11 New Member in Splunk Search 08-04-2016
0 1
0
1
iatwal
how do I change the colors of my bar chart to red, yellow, and green? Here is my query: index=xyxy env=PROD profile...
by iatwal Path Finder in Splunk Search 08-04-2016
0 1
0
1
dbcase
Hi, I have a table with 3 fields in it MSO (a name field) Trend (a Sparkline) Percentage (numeric) When a user cli...
by dbcase Motivator in Splunk Search 08-04-2016
0 2
0
2
ashishlal82
index=bigfix sourcetype=software | eval Hashes_allow_or_deny = if((sha256_allow_or_deny=="*deny*") OR (md5_allow_or_d...
by ashishlal82 Explorer in Splunk Search 08-04-2016
0 4
0
4
sjoerdcopier
I'm trying to use data from a search in a custom command. source | scrapy url=uri This gives me the following erro...
by sjoerdcopier Explorer in Splunk Search 08-04-2016
1 4
1
4
asarran
Hey Fellow Splunkers I have an issue when searching for similar events that are only unique by one character. Exam...
by asarran Path Finder in Splunk Search 08-04-2016
0 3
0
3
tungntran
Hello, I'm trying to change a value of a field using eval case then do a stats count based on that field. I'm getti...
by tungntran Explorer in Splunk Search 08-04-2016
0 2
0
2
sbattista09
I want to alert based off a current value and if that value increases over a threshold within a set time. I want to ...
by sbattista09 Contributor in Splunk Search 08-04-2016
0 4
0
4
ashishlal82
How can I rename a field name with curly braces attached to it e.g. cxy{} and then compare to a field within a looku...
by ashishlal82 Explorer in Splunk Search 08-04-2016
0 1
0
1
duraij
For example: :Report=99,10,99 In this case value 99 occurred twice in this field, so I need to pick this event and...
by duraij Explorer in Splunk Search 08-04-2016
0 2
0
2
jesabs
I have some events which have a field which is named variable. So the event will be like.. field1="a" field2="b" var...
by jesabs Engager in Splunk Search 08-04-2016
0 2
0
2
Lucas_Henry_
I'm trying to use a regular expression to grab words out of a logfile that begin with "FNR" and are exactly 10 alphan...
by Lucas_Henry_ New Member in Splunk Search 08-04-2016
0 2
0
2
dmcbray
I would like to have iplocation fields added to all events when they're ingested and have verified the lookup works i...
by dmcbray New Member in Splunk Search 08-04-2016
0 3
0
3
tattoostreet
Hi, I am browsing information on one of our ticketing server databases, however, when I try to show table contents, ...
by tattoostreet Engager in Splunk Search 08-04-2016
1 5
1
5
SAPrabhakar
I am trying to convert the string "08/04/16 09:40:41.690" to a date in splunk. I think that I am supposed to use some...
by SAPrabhakar Explorer in Splunk Search 08-04-2016
0 2
0
2
mjbaig
Hi guys, I'm really new to Splunk, and probably have no idea what's actually going on with my search, so please bear...
by mjbaig New Member in Splunk Search 08-04-2016
0 5
0
5
dbcase
Hi, First time doing drill downs, so pardon the newbie question. I'm having a tough time grasping the drilldown c...
by dbcase Motivator in Splunk Search 08-04-2016
0 14
0
14
JeffCr
How do I extract the following which always occurs as the last part of the raw text in message e.g "Took 13983.1468ms...
by JeffCr Explorer in Splunk Search 08-04-2016
0 11
0
11
smhsplunk
In previous version of the Splunk one could goto the Edit Icon in each page and could Disable/Enable the drilldown ...
by smhsplunk Communicator in Splunk Search 08-04-2016
0 2
0
2
gesman
When i run search: index=my_summary sourcetype=stash ip=13.13.137.13 | head 5 Job inspector's "normalizedSearch" as ...
by gesman Communicator in Splunk Search 08-04-2016
0 1
0
1
arkadyz1
I have data which contain a field with a lot of values and has duplicates on almost every one - a barcode, scanned in...
by arkadyz1 Builder in Splunk Search 08-04-2016
0 7
0
7
dcascione
Hello Splunk Ninjas I'm trying to create a SPL query that displays the avg and max response time. When I run my sea...
by dcascione Explorer in Splunk Search 08-04-2016
0 7
0
7
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors